Vidar Infostealer Campaign Steals Passwords, Cookies, Crypto Wallets, and Device Data
ID: 7ec10e68-4dc4-59fd-bd8a-4f0947c711ae
STIX ID: report--7ec10e68-4dc4-59fd-bd8a-4f0947c711ae
Feed Name: GBHackers
This report details a currently observed Vidar infostealer campaign that begins with a user-executed MicrosoftToolkit.exe, uses AutoIt-based loaders and disguised .dot→.bat payloads to evade detection, performs process enumeration and anti-analysis checks, exfiltrates credentials, browser cookies and crypto-wallets via C2 hosted on legitimate platforms (Telegram/Steam), and removes artifacts to hinder forensics; the report includes SHA-256 hashes, IPs/domains and MITRE ATT&CK mappings for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
